-
Type:
Bug
-
Status: Closed
-
Priority:
Minor
-
Resolution: Fixed
-
Affects Version/s: 7.3 DXP (7.3.10)
-
Fix Version/s: 7.3.X EE
-
Component/s: Frontend Infrastructure, Security Vulnerability
-
Labels:
-
CVSS Base Score:6.1
-
CVSS Vector String:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
-
7.3 Fix Pack Version:2
Cross-site scripting (XSS) vulnerability in the Frontend Js module's single page application (SPA) implementation in Liferay DXP allows remote attackers to inject arbitrary web script or HTML via the url parameter.